CAS-003 · Question #652
An organization is facing budget constraints The Chief Technology Officer (CTO) wants to add a new marketing platform but the organization does not have the resources to obtain separate servers to…
The correct answer is D. Disparate security requirements. The CISO's primary concern is disparate security requirements. A video-conferencing platform and a marketing platform serve different business functions, handle different types of data, and are subject to different compliance and security controls. Placing them on the same…
Question
An organization is facing budget constraints The Chief Technology Officer (CTO) wants to add a new marketing platform but the organization does not have the resources to obtain separate servers to run the new platform. The CTO recommends running the new marketing platform on a virtualized video-conferencing server because video conferencing is rarely used. The Chief Information Security Officer (CISO) denies this request. Which of the following BEST explains the reason why the CISO has not approved the request?
Options
- APrivilege escalation attacks
- BPerformance and availability
- CWeak DAR encryption
- DDisparate security requirements
How the community answered
(25 responses)- A4% (1)
- B8% (2)
- C12% (3)
- D76% (19)
Explanation
The CISO's primary concern is disparate security requirements. A video-conferencing platform and a marketing platform serve different business functions, handle different types of data, and are subject to different compliance and security controls. Placing them on the same virtualized host means the combined environment must satisfy the stricter security posture of both workloads simultaneously - which may be technically infeasible or introduce unacceptable risk. For example, the marketing platform may require exposure to external internet traffic and integrations with third-party services, while the conferencing server may need stricter access controls. Colocation can lead to policy conflicts, misaligned patching schedules, and regulatory violations. Privilege escalation (A) is a general VM risk but not the primary CISO concern here. Performance/availability (B) is a CTO concern, not a security one. DAR encryption (C) is unrelated to the co-hosting decision.
Topics
Community Discussion
No community discussion yet for this question.